americanexpressconversionepunti36.ink
Appeared in the .ink zone on Saturday, September 19, 2026; by the end of that day the census found boilerplate page. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Domain spells out 'americanexpress' plus the Italian lure phrase 'conversione punti' (points conversion) and a campaign index (36), the exact naming pattern of Amex rewards-points phishing kits; it is registered through a cheap HK retail registrar on AliDNS and currently serves only a bare Kubernetes 403 placeholder, indicating infrastructure staged ahead of content.
Domain is a clear brand-squat typosquat combining 'americanexpress' with obfuscating terms ('conversionepunti36') and a suspicious TLD (.ink). The page returns 403 Forbidden with no functional content, indicating this is a parked or dormant squat domain with no legitimate purpose; the combination of American Express brand-jacking, a suspicious registrar (Dominet HK), and the absence of any real service makes the only plausible intent deception or future phishing setup.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, September 19, 2026

Same data as JSON: /api/zone/domain/americanexpressconversionepunti36.ink. This page is not indexed by search engines and does not link to the site it describes.